Senior Exposure Management Engineer
Core
Governing, assessing, and maintaining enterprise security baseline standards across on-premises, cloud, and hybrid environments to ensure technology assets align with approved security configuration standards and regulatory requirements.
Role type
Senior IC security engineer (exposure management & compliance)
Builds
Enterprise security baseline program, automated compliance validation, and risk-based remediation workflows
Domain
Cybersecurity, Configuration Management, Cloud Security
Deliverable
production ML models | product features | dashboards & analysis | infrastructure
Required skills
Security baseline governance, automated compliance scanning, configuration drift monitoring, exception and risk management, compliance reporting, audit support, cross-functional collaboration, continuous improvement automation, threat-informed exposure reduction
Preferred skills
CISSP, GSEC, GCVA, Azure Security Engineer, AWS Security Specialty, Google Cloud Security Engineer
Technologies
Tenable, Qualys, Rapid7, ServiceNow, Google Cloud, Microsoft Azure, AWS, CIS Benchmarks, SCAP, NIST CSF, MITRE ATT&CK
Responsibilities
Maintain and govern enterprise-approved security baseline standards across operating systems, cloud platforms, applications, databases, and network infrastructure; Conduct ongoing configuration compliance assessments utilizing automated scanning and validation tools; Monitor configuration drift across enterprise assets and provide reporting on deviations; Manage baseline exceptions, compensating controls, and risk acceptance documentation; Develop and maintain configuration compliance metrics, dashboards, and executive reporting; Support reporting through ServiceNow and other enterprise governance platforms; Maintain documentation, evidence, and reporting required to support internal audits, external examinations, and regulatory assessments; Partner with Infrastructure, Cloud, Application, Engineering, and Security teams to support implementation and maintenance of approved security baselines; Identify opportunities to improve assessment coverage, compliance measurement, reporting, and operational efficiencies through automation; Collaborate with Vulnerability Management, Threat Intelligence, Red Team, and Exposure Management teams to prioritize remediation of configuration weaknesses that contribute to exploitable attack paths and elevated risk; Share security baseline best practices, emerging standards, and compliance requirements through documentation, training, and stakeholder engagement
Seniority
Senior, hands-on IC
